1 month ago

Application Security Engineer

Anthropic

On Site
Full Time
$352,500
New York, NY
Apply

Job Overview

Job TitleApplication Security Engineer
Job TypeFull Time
Offered Salary$352,500
LocationNew York, NY

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Anthropic

Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About The Role: Application Security Engineer

The Application Security team is at the forefront of building security into every phase of the software development lifecycle at Anthropic. In this hands-on technical role, you will partner closely with our software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.

Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You'll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions. This high-impact role demands a security practitioner who can think like an attacker, has a developer mindset, and can build strong relationships.

Responsibilities

  • Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries.
  • Lead “shift left” security efforts to build security into the software development lifecycle.
  • Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities.
  • Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices.
  • Manage Anthropic's vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale.
  • Oversee Anthropic's bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community.
  • Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development.
  • Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers.

You May Be a Good Fit If You

  • Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments.
  • Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java).
  • Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle.
  • Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls.
  • Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface.
  • Are keen to distill complex security concepts into clear actions and drive consensus without direct authority.
  • Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education.
  • Have a strong grasp of offensive security to anticipate risks from an adversary's perspective, not just check compliance boxes.
  • Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses.
  • Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives.
  • Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design.

Strong Candidates May Also

  • Have hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP.
  • Possess exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises.
  • Show familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations.
  • Have experience building security tools, applications, and automated tools.
  • Demonstrate solid foundational knowledge of both software and security engineering principles and are keen to continue learning.
  • Exhibit excellent communication skills, able to distill complex security topics for broad audiences.
  • Have worked and thrived in fast-paced environments, and comfortable navigating ambiguity.

Key skills/competency

  • Application Security
  • Cloud Security
  • Threat Modeling
  • Vulnerability Management
  • Bug Bounty
  • Secure SDLC
  • Python/Go/Rust/Java
  • AI/ML Security
  • Offensive Security
  • Container Security

Tags:

Application Security Engineer
threat modeling
secure design
vulnerability management
bug bounty
secure coding
risk assessment
security policy
security awareness
offensive security
SDLC
Python
Rust
Go
Java
cloud security
Kubernetes
Docker
AWS
GCP
AI/ML security

Share Job:

How to Get Hired at Anthropic

  • Research Anthropic's culture: Study their mission on safe AI, values, recent research, and employee testimonials on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight application security, cloud security, AI/ML security expertise, and programming language proficiency for Anthropic roles.
  • Showcase problem-solving skills: Prepare to discuss complex security challenges, threat modeling, and your ability to build pragmatic defenses.
  • Emphasize collaboration and communication: Demonstrate your experience working cross-functionally and distilling complex security concepts effectively.
  • Understand AI/ML security: Familiarize yourself with Anthropic's research and potential AI/ML specific security risks and mitigations.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background